What happened?
Microsoft said a critical vulnerability in Zimbra Collaboration Suite is being actively exploited by attackers. Tracked as CVE-2026-73570, the flaw lets attackers remotely issue operating system commands without authentication. Attackers are using it to obtain email backups and authentication credentials of vulnerable organizations.
Patch delayed
Zimbra maintainer Synacor issued a patch on July 20 but did not disclose the vulnerability for more than three weeks afterward, making it harder for organizations to defend themselves.
How many servers are affected?
The security-focused Shadowserver Foundation said its scans found 274 separate Zimbra instances had been compromised. The number of servers running the software fluctuated from 19,000 in the week following the patch to about 12,000 in the weeks after that. Currently, Shadowserver is tracking about 10,000 instances.
How the attack worked
From July 28 to August 7, Microsoft detected two distinct scanning tools probing the Internet for vulnerable endpoints. Attackers first validated their exploit by sending HTTP requests and DNS, ICMP, and out-of-band identity checks. They then began using their command injection capability to install malicious payloads.



